Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h6wp-xwgx-g8g4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

Improper access control vulnerability in ESConfigTool.exe in ENS for Windows all current versions allows a local administrator to alter the ENS configuration up to and including disabling all protection offered by ENS via insecurely implemented encryption of configuration for export and import.

Improper access control vulnerability in ESConfigTool.exe in ENS for Windows all current versions allows a local administrator to alter the ENS configuration up to and including disabling all protection offered by ENS via insecurely implemented encryption of configuration for export and import.

EPSS

Процентиль: 12%
0.00039
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 6.5
nvd
почти 6 лет назад

Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrator to alter ENS configuration up to and including disabling all protection offered by ENS via insecurely implemented encryption of configuration for export and import.

EPSS

Процентиль: 12%
0.00039
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-732